Sceawere
Vulnerability Detail
CVE-2026-88783UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Kubio AI Stored XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 13h ago
- Vendor
- Unknown
- Product
- Kubio AI Page Builder
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Kubio AI Page Builder WordPress plugin before 2.9.3 does not limit its widening of the allowed HTML elements to the editor context, so the wider set is applied when filtering content submitted by unauthenticated users as well, allowing them to store markup which the Kubio AI Page Builder WordPress plugin before 2.9.3's own script later executes in the browser of any visitor, or of an administrator reviewing the still-unapproved submission.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-03T06:16:45.037Z",
"pubdate": "2026-10-03T06:16:45.037Z",
"executiveSummary": "The Kubio AI Page Builder WordPress plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper input sanitization and an overly permissive HTML filtering configuration.\nThis vulnerability exists in versions prior to 2.9.3 and allows unauthenticated attackers to inject and store malicious HTML and JavaScript payloads within the plugin's content processing pipeline.\nBecause the plugin applies an expanded set of allowed HTML elements to all content submissions, including those from unauthenticated users, the malicious scripts are persisted in the database.\nWhen a victim, such as a site administrator or a regular visitor, views the affected content, the stored script executes within the context of the user's browser session.\nThe impact is significant, as it can lead to full account takeover, unauthorized actions performed on behalf of the victim, sensitive data exfiltration, and the compromise of administrative sessions.\nThis vulnerability represents a critical risk to site integrity and user security, as no authentication is required for an attacker to successfully inject the malicious payloads.",
"technicalDetails": "The root cause of this vulnerability is an insecure implementation of HTML filtering logic within the Kubio AI Page Builder plugin. Specifically, the plugin introduces an expanded, permissive set of allowed HTML tags and attributes intended for the editor's administrative context. However, the plugin fails to restrict this permissive filtering mechanism to the editor's administrative interface, inadvertently applying it to all input sanitization processes, including those handling content submitted by unauthenticated users.\nIn a standard WordPress installation, input is typically sanitized using functions like wp_kses() to ensure that only safe, predefined HTML elements are stored in the database. By extending the permitted markup set globally, the Kubio AI Page Builder plugin bypasses these protective controls, allowing for the injection of executable elements such as script tags or event handlers (e.g., onerror, onload) into the database.\nThe attack flow proceeds as follows: First, an unauthenticated attacker identifies an input vector handled by the plugin that processes and saves user-supplied content to the database. Second, the attacker crafts a malicious payload containing JavaScript disguised within the permitted, yet non-sanitized, HTML structure. Third, because the plugin's filtering logic is globally widened, the input passes validation without being stripped of the malicious executable markup. Fourth, the malicious script is stored in the WordPress database.\nThe payload remains dormant until a user, such as an administrator or a visitor, navigates to the page or post where the malicious content is rendered. Upon rendering, the browser interprets the injected HTML and executes the embedded script in the security context of the victim's session. If the victim is an administrator, the attacker can leverage the script to perform privileged actions, such as creating new administrative users, modifying plugin settings, or redirecting site traffic. Even if the victim is a regular visitor, the attacker can hijack session cookies, phish for credentials, or engage in drive-by downloads. This vulnerability affects all versions of the Kubio AI Page Builder plugin prior to 2.9.3, and because the vulnerable component is active regardless of current user privilege, it remains highly exploitable across any publicly accessible WordPress instance utilizing the plugin."
}